Medium severity5.3NVD Advisory· Published May 9, 2022· Updated Jun 17, 2026
CVE-2019-25060
CVE-2019-25060
Description
The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
wp-graphql/wp-graphqlPackagist | < 0.3.5 | 0.3.5 |
Affected products
3- WordPress/WPGraphQL plugindescription
Patches
Vulnerability mechanics
References
4- github.com/wp-graphql/wp-graphql/pull/900nvdExploitThird Party AdvisoryWEB
- wpscan.com/vulnerability/393be73a-f8dc-462f-8670-f20ab89421fcnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-w3xg-7q6m-3xwpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-25060ghsaADVISORY
News mentions
0No linked articles in our index yet.